Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Declined]rule(list network_tool_binaries): Add some network tools to detect suspicious network activity #973

Closed
wants to merge 1 commit into from

Conversation

rung
Copy link
Contributor

@rung rung commented Dec 13, 2019

Signed-off-by: Hiroki Suezawa suezawa@gmail.com

What type of PR is this?
/kind rule-update

Any specific area of the project related to this PR?
/area rules

What this PR does / why we need it:

What this PR does

  • Add network tool binaries to detect suspicious network process.

Why we need it

  • I added some common tools which attackers often use.

Which issue(s) this PR fixes:

Fixes #

Special notes for your reviewer:

Does this PR introduce a user-facing change?:

rule(list network_tool_binaries): Add some network tools to detect suspicious network activity.

Signed-off-by: Hiroki Suezawa <suezawa@gmail.com>
@poiana
Copy link
Contributor

poiana commented Dec 13, 2019

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
To fully approve this pull request, please assign additional approvers.
We suggest the following additional approver: mstemm

If they are not already assigned, you can assign the PR to them by writing /assign @mstemm in a comment when ready.

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@poiana poiana requested review from fntlnz and mstemm December 13, 2019 14:10
@poiana poiana added the size/XS label Dec 13, 2019
@rung rung closed this Dec 13, 2019
@rung rung deleted the add-network-tools branch December 13, 2019 14:11
@rung rung restored the add-network-tools branch December 13, 2019 14:11
@rung rung reopened this Dec 13, 2019
@rung
Copy link
Contributor Author

rung commented Dec 13, 2019

(I closed this PR by mistake, so I reopened it)

@leodido
Copy link
Member

leodido commented Dec 13, 2019

/cc @Kaizhe

/cc @leodido

1 similar comment
@leodido
Copy link
Member

leodido commented Dec 13, 2019

/cc @Kaizhe

/cc @leodido

@poiana poiana requested review from Kaizhe and leodido December 13, 2019 17:14
@@ -2281,7 +2281,7 @@
tags: [network, k8s, container, mitre_port_knocking]

- list: network_tool_binaries
items: [nc, ncat, nmap, dig, tcpdump, tshark, ngrep]
items: [nc, ncat, nmap, dig, tcpdump, tshark, ngrep, telnet, ssh, mitmproxy, socat]
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ssh might be false positive prone as the list is also used in the rule Launch Suspicious Network Tool on Host.

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@Kaizhe Thank you.
and very sorry 🙇. Because I re-forked this repo, I Couldn't push new commit to this PR.
So I recreated new PR.
#975

@rung rung changed the title rule(list network_tool_binaries): Add some network tools to detect suspicious network activity [Declined]rule(list network_tool_binaries): Add some network tools to detect suspicious network activity Dec 16, 2019
@rung rung closed this Dec 16, 2019
@fntlnz fntlnz added this to the 0.19.0 milestone Jan 22, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants